GRC Analyst

Overview

The GRC Analyst will play a pivotal role in enhancing cyber and technology risk management within a leading global organization. This contract position involves collaborating with various stakeholders to build and embed a robust risk function, ensuring effective identification, assessment, reporting, and management of technology and cyber risks. The Analyst will engage closely with senior leadership and will thrive in a hybrid working environment.

Responsibilities

  • Build, develop, and maintain cyber and technology risk registers.
  • Identify, assess, and document risks across technology, cyber security, and business change initiatives.
  • Produce clear risk statements covering threats, vulnerabilities, business impact, and existing controls.
  • Develop and maintain risk treatment plans, ensuring actions are owned and delivered.
  • Track remediation activities and challenge overdue actions where required.
  • Facilitate risk reviews and workshops with technical and non-technical stakeholders.
  • Support Cyber Assessment Framework (CAF) activities, evidence gathering, and remediation tracking.
  • Produce high-quality risk reporting and management information for senior leadership.

Requirements

  • Proven experience as a GRC Analyst, Technology Risk Analyst, Cyber Risk Analyst, or Information Security Risk Analyst.
  • Strong practical experience owning and maintaining risk registers.
  • Demonstrable experience conducting risk assessments and developing risk treatment plans.
  • Ability to write meaningful risk statements and present complex risks clearly.
  • Strong stakeholder management skills with the confidence to operate independently from day one.
  • Experience tracking remediation and mitigation activities through to completion.
  • Excellent communication and reporting skills.
  • Familiarity with NCSC Cyber Assessment Framework (CAF), ISO 27001, and NIST Cybersecurity Framework.